There is a heap-based buffer over-read in the Exiv2:...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Sep 29, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 2, 2023
There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
References